Hugging Face confirmed an intrusion that Tailscale's mesh networking didn't block, and Anthropic published details on three real-world cybersecurity incidents surfaced through its own model evaluations. OpenAI says it disrupted a criminal scam operation running on its tools, while Ars Technica reports AI scammers are now outperforming humans at building trust with victims. Add in a pre-auth RCE found in Apple Screen Sharing and a Wired report tying cyberattacks on seven states' water systems to Iran, and the pattern is the same: AI is showing up on both sides of the security fight at once.
On the model side, DeepMind shipped Gemini Robotics ER 2, adding video understanding and multi-robot task orchestration, and launched Lyria 3.5 inside Google Flow Music with upgraded vocals and lyric control. OpenAI pushed GPT-5.6 as a price-performance update and detailed how avatarin built a 24/7 retail agent on GPT-Realtime. Less encouraging: Google Earth's new AI image tools let anyone fabricate convincing fake satellite imagery, according to 404 Media.
Down in the workshop, a 15-year-old built a working cycloidal gearbox from scratch, someone got 25 Gbps Thunderbolt Ethernet running on a Mac Studio, and Gander landed as an Android file viewer that asks for zero permissions. A RTX 5060 Ti survived being bent in half in a car crash, fixed with a single memory chip resolder. And astronomers announced the first confirmed exomoon detection, while Ars Technica covered a new full-color night vision goggle design.